2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-9483HIGH8.8A flaw has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1...
CVE-2025-9482HIGH8.8A vulnerability was detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04....
CVE-2025-9481HIGH8.8A security vulnerability has been detected in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0....
CVE-2025-8424HIGH8.7Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway when an attacker ca...
CVE-2025-50753HIGH8.4Mitrastar GPT-2741GNAC-N2 devices are provided with access through ssh into a restricted default shell.The command "devi...
CVE-2025-29992HIGH7.5Mahara before 24.04.9 exposes database connection information if the database becomes unreachable, e.g., due to the data...
CVE-2025-38676HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Avoid stack buffer overflow from kernel ...
CVE-2025-53419HIGH7.8Delta Electronics COMMGR has Code Injection vulnerability.
CVE-2025-53418HIGH8.6Delta Electronics COMMGR has Stack-based Buffer Overflow vulnerability.
CVE-2025-5931HIGH8.8The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and...
CVE-2025-9172HIGH7.5The Vibes plugin for WordPress is vulnerable to time-based SQL Injection via the ‘resource’ parameter in all versions up...
CVE-2025-9461HIGH7.5A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/...
CVE-2025-9443HIGH8.8A flaw has been found in Tenda CH22 1.0.0.1. This vulnerability affects the function formeditUserName of the file /gofor...
CVE-2025-8627HIGH8.8The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off conditio...
CVE-2025-57809HIGH7.5XGrammar is an open-source library for efficient, flexible, and portable structured generation. Prior to version 0.1.21,...
CVE-2025-57805HIGH8.7The Scratch Channel is a news website. In versions 1 and 1.1, a POST request to the endpoint used to publish articles, c...
CVE-2025-6188HIGH7.5On affected platforms running Arista EOS, maliciously formed UDP packets with source port 3503 may be accepted by EOS. U...
CVE-2025-9417HIGH8.8A weakness has been identified in itsourcecode Apartment Management System 1.0. This issue affects some unknown processi...
CVE-2025-57811HIGH7.2Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is...
CVE-2025-57802HIGH8.7Airlink's Daemon interfaces with Docker and the Panel to provide secure access for controlling instances via the Panel. ...
CVE-2025-50383HIGH8.1alextselegidis Easy!Appointments v1.5.1 was discovered to contain a SQL injection vulnerability via the order_by paramet...
CVE-2025-6737HIGH7.2Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access tokens across multiple tenan...
CVE-2025-57760HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. A privilege escalation vulnerability exis...
CVE-2025-29421HIGH7.5PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
CVE-2025-29420HIGH7.5PerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now